Conversation
|
I'm 99% sure this allows you to execute arbitrary PHP, just win some extra steps. There are various config variables that let you read from (e.g. I think we should figure out a different way of whitelisting (#51 (comment)) or something. |
As a V+1 user I can create a patch that does the same thing, so surely this is no less secure? |
|
Yes but we won't demo your patch unless it has V+2. |
|
I mean V+2 - you can write a pretty malicious patch and still get V+2 as long as you are trusted. If you aren't trusted you can't create a patch demo anyway. |
|
The problem with the email whitelist is that OAuth doesn't give us the user email, so we would need to create a separate SUL-based account whitelist. |
dbe9d3e to
9282fd7
Compare
|
See #112 |
Fixes #19